VULNERABILITY INTELLIGENCE

CVE-2016-4563

CVSS score8.8 HIGH
EPSS probability2.58%
CISA KEVNot currently listed
Published2016-06-04
Last modified2026-06-17
CVSS vectorCVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Description

The TraceStrokePolygon function in MagickCore/draw.c in ImageMagick before 6.9.4-0 and 7.x before 7.0.1-2 mishandles the relationship between the BezierQuantum value and certain strokes data, which allows remote attackers to cause a denial of service (buffer overflow and application crash) or possibly have unspecified other impact via a crafted file.

Weakness classification

  • CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer

Primary references